Вы находитесь на странице: 1из 17

Mac OS X Server as an Advanced Mail Server

insecure Internet SSL/VPN VPN Mail application SSL WebMail

secure local area network

Andr Aulich Freelance Apple Consultant aaulich@mac.com www.andre-aulich.de

Market needs
user experience
secure mail transfer virus and spam lter auto-replies (vacation notices) group mail accounts shared IMAP folders internal and external access using mail application or Webmail ease of use
2004 www.andre-aulich.de

additional administrative demands


stable overall service backup and disaster recovery strategy support for email addresses like
rstname.lastname@domain.co.uk

server shouldnt need much support after rst setup redundancy

Standard Mac OS X Mail Server Setup - using internal tools -

DEMO

2004 www.andre-aulich.de

Standard mail setup


SMTP IN local Mac OS X Server

Postfix

recipient local user

recipient external user

Cyrus

external SMTP server

2004 www.andre-aulich.de

Standard mail setup


incoming SMTP mail recipient is local user sender IP address accepted message size accepted

Postx

recipient is external user sender IP address not accepted sender has no local user account not SSL encrypted

sender IP address not accepted message size not accepted

sender IP address accepted sender has local user account SSL encrypted

Cyrus stores mails for local users


in users' inboxes

SMTP server of external user

Mail delivery using POP or IMAP SSL, and/or VPN tunnel

any kind of delivery

Mail client using mail application or Webmail interface

external mail recipient

2004 www.andre-aulich.de

Advanced Mac OS X Mail Server Setup - using internal and external tools -

DEMO

2004 www.andre-aulich.de

Advanced mail setup


SMTP IN local Mac OS X Server Postfix recipient external user

recipient local user

Sanitizer

Virex or Sophos Procmail Spam Assassin

Razor

Cyrus

external SMTP server

2004 www.andre-aulich.de

Advanced mail setup - feature list



secure mail transfer using SSL and/or VPN state-of-the-art virus and mail lters easy-to-use webmail interface exible mail addresses like rstname.lastname@domain.co.uk powerful backup and disaster recovery strategies vacation notices controlled by users powerful mailing list management group mail accounts and shared IMAP folders
2004 www.andre-aulich.de

Advanced mail setup - Alternative


SMTP IN local Mac OS X Server external SMTP server

recipient local user Postfix

amavisd-new

ClamAV

Spam Assassin

Razor

Cyrus

2004 www.andre-aulich.de

Finetuning

add log rolling SpamAssassin can be trained add support for multiple domains server-based rules (using CLI) encrypt mails to external recipients using sender certicates
2004 www.andre-aulich.de

Tiger announcements

see http://www.apple.com/uk/server/macosx/tiger/ SpamAssassin will be included with Mac OS X Server Support for mail server clustering added support for virtual hosts

2004 www.andre-aulich.de

Commercial alternatives

Kerio MailServer, www.kerio.com CommuniGate Pro, www.stalker.com 4D Mail, www.4D.com PostOfce, www.tenon.com

2004 www.andre-aulich.de

General security advisory



security on mobile client computers security on other peoples computers Limiting server access to VPN and SSL ports Secure other services using SSL

2004 www.andre-aulich.de

Summary

Mac OS X Server is a powerful, enterprise-level mail server many functions are available via the GUI more functions can be added using industry-standard, free-of-charge Open Source tools The complete system is easy to use for the clients Mac OS X Server offers secure and exible mail solutions

2004 www.andre-aulich.de

Tools you need



Mac OS X Server (optional) Anomy Sanitizer: http:// mailtools.anomy.net/ Virus scanner

Virex (http://www.mac.com), Sophos-Antivirus, ClamAV, etc.

SpamAssassin: http:// spamassassin.apache.org/ Razor: http://razor.sourceforge.net/ (optional) amavisd-new: http://ijs.si/ software/amavisd/

2004 www.andre-aulich.de

Resources

Copy of this presentation and basic conguration guide for the described setup: http://www.andre-aulich.de/ mailserveren1.html 'Sanitizing Mail on Panther Server' by Jason Deraleau: http://www.macdevcenter.com/pub/a/mac/2004/01/27/ sanitize_mail.html 'Fighting Spam on Mac OS X Server': http://developer.apple.com/server/ghting_spam.html 'Using Open Source Tools to Filter Email on Mac OS X Server': http://developer.apple.com/server/virusltering.html test of commercial mail servers: http://www.macworld.com/2004/03/reviews/emailservers 'Spam/Virus controls with OS X Server': http://www.afp548.com/article.php?story=20041104095414942 'Use Cyradm to Manage your Cyrus Mailboxes': http://www.afp548.com/article.php?story=20040814204411280 'OS X Server 10.3 Mail Backup': http://www.afp548.com/article.php?story=2004092303182960 'Log Rolling made easy': http://www.afp548.com/article.php?story=20040916181619888 'Sieve Installer': http://www.afp548.com/article.php?story=20040721014726822 'Cyrus IMAP Mailbox Recovery': http://www.afp548.com/article.php?story=20040824063737872 'The great big Panther SSL article': http://www.afp548.com/article.php?story=20040722080720854 Squirrelmail-Plugins: http://www.squirrelmail. How to Set Up Encrypted Mail on Mac OS X: http://www.macdevcenter.com/pub/a/mac/2003/01/20/mail.html

2004 www.andre-aulich.de

Q&A

Вам также может понравиться